Malicious PDF — malware analysis report

Static analysis result for SHA-256 92e07b1bbb262a76…

MALICIOUS

PDF

26.1 KB Created: 2009-10-20 17:04:33 +04:00 Authoring application: pageDolor (via fced4f35799409dd854ebeaea7db546d)
MD5: 1d3cedba9ebb1059a99d33d6e6004aa5 SHA-1: d0e06046ed882e9273f7b5f46f86acbe97abe6db SHA-256: 92e07b1bbb262a765092a267356703a8b1dc856e9caaeead9f99a7c768d516c9
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical ClamAV detection and high ML classifier score indicate a malicious PDF. The presence of embedded JavaScript, flagged by multiple heuristics, strongly suggests an exploit is being used to execute arbitrary code. The JavaScript is likely responsible for downloading and executing a second-stage payload, as indicated by the 'ML_NYX_PDF_MALICIOUS' heuristic and the 'Pdf.Exploit.Agent-1710' ClamAV signature. The document body is unreadable, so the exact lure cannot be determined.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9976

Heuristics 4

  • ClamAV: Pdf.Exploit.Agent-1710 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-1710
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Optional Content Group with action trigger low PDF_OPTIONAL_CONTENT
    Optional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0018_000.js
efd1ecbebd2cf79f8f154cb746c9dfc98bde08950ef360f557b5c813d63e2a09
pdf-javascript-stream PDF /JS object 18 at offset 0x330F 11582 bytes